2.6

CVE-2006-1115

nCipher HSM before 2.22.6, when generating a Diffie-Hellman public/private key pair without any specified DiscreteLogGroup parameters, chooses random parameters that could allow an attacker to crack the private key in significantly less time than a brute force attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NcipherMscapi Csp Version5.50
NcipherMscapi Csp Version5.54
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.19% 0.638
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19137
Patch
Vendor Advisory
http://securitytracker.com/id?1015719
Patch
Vendor Advisory
http://www.ncipher.com/resources/95/sa12_insecure_generation_of_diffiehellman_keys
Patch
Vendor Advisory
http://www.securityfocus.com/archive/1/427146/100/0/threaded
http://www.securityfocus.com/bid/17006
Patch
http://www.vupen.com/english/advisories/2006/0862
https://exchange.xforce.ibmcloud.com/vulnerabilities/25060